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tasks each seek to further identify different portions of one of a cryptographic analysis 
and an emulation analysis. 

37. (Currently Amended) Apparatus as claimed in claim 3 1 , wherein said on-access 
malware scan of said computer file further seeks to identify one or more of: 

(i) a computer virus; 

(ii) a Trojan computer program; 

(iii) a worm computer program; 

(iv) a banned computer program; and an e-mail containing banned content, 

38. (Original) Apparatus as claimed in claim 31, wherein one or more of said tasks 
are further divided into sub-tasks. 

39. (Cmiently Amended) Apparatus as claimed in claim 3 1 , wherein a task is further 
selected to be issued to a different computer in dependence upon one or more of: 

(i) a measure of available processing resources at said different computer; 

(ii) a measure of communication channel bandwidth to said different computer; 

(iii) a measure of task complexity of said task to be issued; and 

(iv) a measure of processor utilization of said different computer. 

40. (Currently Amended) Apparatus as claimed in claim 3 1 , wherein said scan divider 
does not further divide said on-access malwaxe scan if said on-access malware scan is 
detected as having a complexity below a predetermined threshold level 

4 1 . (Currently Amended) Apparatus as claimed in claim 40, wherein said complexity 
is further determined as a function of one or more of: 

(i) a file type of said computer file; 

(ii) whether said computer file contains any embedded computer files; 

(iii) a level of nesting of embedded files within said computer file; 

(v) an initial scanning attempt of said computer file taking longer than a 
predetermined time; and 
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(vi) processor utilization of a computer initiating said request. 

42. (Cunently Amended) Apparatus as claimed in claim 3 1 , wherein said result 
collator fi^ther,tenninates any outstanding tasks if a task result is received indicating 
detection of malware within said computer file. 

43. (Previously Presented) Apparatus for performing an on-access malware scan of a 
computer file, said apparatus comprising: 

(i) a task receiver operable to receive a request to perform a malware scanning 
task that is part of an on-access malware scan of a computer file requested by another 
computer; 

(ii) a scanner operable to perform said malware scanning task; and 

(iii) a result returner operable to retum a result of said malware scanning task; 
wherein said malware scanning task is one of a plurality of malware scanning 

tasks that are each part of said on-access malware scan; 

wherein a plurality of malware scanning task results corresponding to said 
plurality of malware scanning tasks are collated to form a scan result corresponding to 
said on-access malware scan. 

44. (Currently Amended) Apparatus as claimed in claim 43, wherein said computer 
file is fiirther d ivided into a plurality of component computer files to be separately 
scaimed as separate malware scanning tasks. 

45. (Currently Amended) Apparatus as claimed in claim 43, wherein said on-access 
malware scan of said computer file is further divided into said plurality of on-access 
malware scaiming tasks for identifying different properties of said computer file, said 
plurality of on-access malware scannmg tasks being separately performed. 

46. (Currently Amended) A computer program product as claimed in claim 1 , 
wherein said scan dividing logic further divides said on-access malware scan in response 
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to a complexity metric exceeding a predetermined threshold, where the complexity metric 
is dependent on at least one parameter. 

47. (Currently Amended) A computer program product as claimed in claim 46, 
wherein the parameter Jaraer includes at least one of a computer file type, a level of 
nesting of embedded computer files, an initial attempt to scan said computer file which 
exceeded a predetermined time, and a level of utilization of a local processor. 

48. (Currently Amended) A computer program product as claimed in claim 16,fo r 
controlling a computer, said computer program product comprising: 

(\\ scan request receiving logic operable to receive a req uest to perform an on- 
access malware scan upon a computer file to which access is to be made ; 

(V\\ scan dividing logic operable to divide said on-acces s malwate scan into a 
p^iiiralitv of tasks: 

(u\) ta^k issuin g logic operable to issue said plura lity of tasks to be performed by. 
a pluralitv of different computers: and 

result collating logic operable to collate a plurality of task results 
corres ponding to said plurality of tasks and re ceived firom said plurality of different 
computers to form a scan result corresponding to s aid on-access malware scan; 

wherein said scan dividit^g logic divides said on-access malware scan in response 
to a complexity metric exceeding a predetermined th reshold, where the complexity metric 
is dependent on at least one parameter: 

wherein the complexity metric is dependent on a plurality of parameters including 
a computer file type, a level of nesting of embedded computer files, an initial attempt to 
scan said computer file which exceeded a predetermined time, and a level of utilization of 
a local processor. 

49. (Currently Amended) A computer program product oq claim e d in c laim ^ 6,fo r 
controlling a computer, said computer program product comprising: 

(i) scan request receiving logic operable to receive a re quest to perform an on- 
access malware scan upon a computer file to which access is to be made: 
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(ii) scan dividing logic operable to divide said oa-access malware scan into a 
plurality of tasks: 

(in) task issuing loEic operable to issue said plurality of tasks to be performed by 
a plurality of different computers: and 

(iv) result collating logic operable to collate a plurality of task results 
corresponding to said plurality of tasks and received from said plurality of different 
computers to form a scan result corresponding to said on-access malware scan: 

wherein said scan dividing logic divides said on-access malware scan in response 
to a complexity metric exceeding a predetermined threshold, where the complexity metric 
is dependent on at least one parameter: 

wherein an amount said complexity metric exceeds said predetermined threshold 
determines a number of tasks into which said on-access malware scan is divided. 

50. (Currently Amended) A computer program product as claimed in claim 1 , 
wherein if one of said plurality of task results furthex indicates that malware has been 
detected in said computer file, remaining tasks in said pliu-ality of tasks that are pending 
are terminated. 

5 1 , (Currently Amended) A computer program product as claimed in claim 1 , 
wherein said plurality of tasks are further distributed among said plurality of different 
computers via a network. 
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